Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Safeguard Enterprise Data Exchange

It's been noticed that we have Data Exchange licenses - unfortunately I don't think it was configured/installed when Utimaco services was on site managing our install of the Safeguard Enterprise 5.35 infrastructure.  I've looked through the documentation and can't easily see how to enable and begin using this feature. 

Any suggestions on where to start?

Thanks!

:2215


This thread was automatically locked due to age.
Parents

  • ssij wrote:

    Michelle,

    The Sophos guys can correct me if I am wrong, but I believe that by default, when the SGN client is installed on a machine it will install the Data Exchange feature (unless explicitly disabled during the install).  You can check individual machines in the management console to see if they have the Data Exchange feature installed, and if not, you could use the SGNClient.msi file to install those components.

    As for enabling it, you would need to create a policy that sets file encryption for removable media to start using the Data Exchange.


    Hi ssij,

    Thank you for posting a response to help others in the community! This is exactly how the forum is to be used.

    I would like to add a couple supporting comments to your posting. During a manual installation of the SGN Client, the Typical option in the wizard will only include Device Encryption -> Volume Based Encryption. The Customer option in the wizard will enable someone to select other components such as Data Exchange or Configuration Protection.

    If installing from a script, the ADDLOCAL parameter can be used to include the components to be installed. I'm guessing that Michelle is using a script or a packaging tool. If so, to get the binaries on the client, all you need to do is include the SecureDataExchange feature in your script. Refer to Chapter 12 of the SGN_Installation Guide.

    The second piece of the puzzle necessary to get SGN DX working, as ssij wrote, is a Device Protection policy which selects either Removable Media or Optical Media as the target. Configure the policy as desired and then apply to a location in Users & Computers which includes user objects and computer objects. The Device Protection policy needs a computer object to activate the policy, but there are some security policy settings that are user object based as well.

    Please let us know if you have any questions.

    :2275
Reply

  • ssij wrote:

    Michelle,

    The Sophos guys can correct me if I am wrong, but I believe that by default, when the SGN client is installed on a machine it will install the Data Exchange feature (unless explicitly disabled during the install).  You can check individual machines in the management console to see if they have the Data Exchange feature installed, and if not, you could use the SGNClient.msi file to install those components.

    As for enabling it, you would need to create a policy that sets file encryption for removable media to start using the Data Exchange.


    Hi ssij,

    Thank you for posting a response to help others in the community! This is exactly how the forum is to be used.

    I would like to add a couple supporting comments to your posting. During a manual installation of the SGN Client, the Typical option in the wizard will only include Device Encryption -> Volume Based Encryption. The Customer option in the wizard will enable someone to select other components such as Data Exchange or Configuration Protection.

    If installing from a script, the ADDLOCAL parameter can be used to include the components to be installed. I'm guessing that Michelle is using a script or a packaging tool. If so, to get the binaries on the client, all you need to do is include the SecureDataExchange feature in your script. Refer to Chapter 12 of the SGN_Installation Guide.

    The second piece of the puzzle necessary to get SGN DX working, as ssij wrote, is a Device Protection policy which selects either Removable Media or Optical Media as the target. Configure the policy as desired and then apply to a location in Users & Computers which includes user objects and computer objects. The Device Protection policy needs a computer object to activate the policy, but there are some security policy settings that are user object based as well.

    Please let us know if you have any questions.

    :2275
Children
No Data